Stripe
Payment processing and subscription billing
Ireland and United States (global payment network)
Security & compliance
What we build, what we publish, what we plan. Every claim on this page reflects actual shipped controls or documented in-progress work, nothing is overstated.
Section 1
These are shipped capabilities, not roadmap items. Each is verifiable in product or code.
Section 2
14 ISMS security policies aligned to ISO 27001:2022 Annex A controls (audit planned). Published at /docs/security/policies/.
Full policy documents available via the compliance document library once audit work is complete. Copies available to enterprise prospects on request.
Section 3
All subprocessors with current active status. Full list including planned processors at /trust/subprocessors. Change notifications sent 30 days in advance.
Payment processing and subscription billing
Ireland and United States (global payment network)
Virtual private server hosting (production application + database) and managed mailbox
European Union (Lithuania) and United States
Transactional email delivery (account verification, password reset, notifications)
United States
Object storage for file attachments and exports
United States (EU-region option planned for Enterprise)
Domain registrar and authoritative DNS
United States
Application observability — traces, logs, metrics. Operated by QEHS on its own infrastructure.
Same infrastructure as the production application (United States at launch)
Customer support inbox. Operated by QEHS on its own infrastructure.
Same infrastructure as the production application (United States at launch)
Sales-call scheduling. Operated by QEHS on its own infrastructure.
Same infrastructure as the production application (United States at launch)
Section 4
What we are working toward, honest about what is planned versus what is complete.
Section 5
Security questions or concerns: security@qehsethos.com
Found a vulnerability? Read our responsible disclosure policy. We respond within 2 business days and do not pursue good-faith researchers.
Machine-readable contact: /.well-known/security.txt